Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2020-9423EPSS 5% LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logic… Logicaldoc 8.3.3+ Fix from $2,3002020-03-18 HIGH 7.2 CVE-2019-11074 A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrar… Prtg Network Monitor after 19.1.49 Fix from $1,9502020-03-17 MEDIUM 6.5 CVE-2020-9472 Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality. Umbraco Cms No fix yet Fix from $1,6002020-03-16 HIGH 8.8 CVE-2020-9471 Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. Umbraco Cms No fix yet Fix from $1,9502020-03-16 HIGH 7.2 CVE-2020-5844EPSS 30% index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP script… Pandora Fms No fix yet Fix from $1,9502020-03-16 HIGH 8.8 CVE-2020-10557 An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section i… Acontent after 1.4 Fix from $1,9502020-03-16 HIGH 7.2 CVE-2020-10562 An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads. Grr 3.4.1c+ Fix from $1,9502020-03-13 HIGH 7.2 CVE-2020-10386EPSS 12% admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php fi… Phpkb No fix yet Fix from $1,9502020-03-12 HIGH 8.8 CVE-2015-7339 JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes… Jce after 2.5.2 Fix from $1,9502020-03-09 HIGH 8.8 CVE-2015-7341 JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. Jnews 8.5.0+ Fix from $1,9502020-03-09 CRITICAL 9.8 CVE-2016-6918 Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. ( Markvision Enterprise 2.4.1+ Fix from $2,3002020-03-09 HIGH 8.8 CVE-2020-5256 BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to exe… Bookstack 0.25.3+ Fix from $1,9502020-03-09 CRITICAL 9.8 CVE-2020-10224EPSS 5% An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exp… Online Book Store No fix yet Fix from $2,3002020-03-08 CRITICAL 9.8 CVE-2020-10225 An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploi… Job Portal No fix yet Fix from $2,3002020-03-08 CRITICAL 9.8 CVE-2020-9380 IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. Web Tv Player after 2020-02-22 Fix from $2,3002020-03-05 HIGH 8.8 CVE-2018-19798 Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the a… Fleet Maintenance Management after 1.2 Fix from $1,9502020-03-02 HIGH 7.2 CVE-2020-8500 In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The ven… Pandora Fms No fix yet Fix from $1,9502020-03-02 HIGH 8.8 CVE-2018-17058 An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload featu… Jaba Xpress after 2018-09-14 Fix from $1,9502020-03-02 CRITICAL 9.8 CVE-2016-11020 Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution. Kunena 5.0.4+ Fix from $2,3002020-02-25 MEDIUM 6.5 CVE-2020-5188 DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. Dotnetnuke after 9.4.4 Fix from $1,6002020-02-24 MEDIUM 5.5 CVE-2020-9320 Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for E… Anti Malware Sdk 8.3.54.138+ Fix from $1,6002020-02-20 HIGH 8.8 CVE-2015-0258 Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticate… Debian Linux 2.1+ Fix from $1,9502020-02-17 CRITICAL 9.8 CVE-2011-4908EPSS 56% TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. Tinybrowser 1.5.13+ Fix from $2,3002020-02-12 CRITICAL 9.8 CVE-2011-4906EPSS 10% Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. Tinybrowser 1.5.13+ Fix from $2,3002020-02-12 CRITICAL 9.8 CVE-2013-2057 YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability Yabb after 2.5.2 Fix from $2,3002020-02-11 CRITICAL 9.8 CVE-2013-3684EPSS 19% NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload Nextgen Gallery 1.9.13+ Fix from $2,3002020-02-11 CRITICAL 9.8 CVE-2013-0803EPSS 75% A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. Polarbear Cms No fix yet Fix from $2,3002020-02-11 CRITICAL 9.8 CVE-2019-20451EPSS 8% The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requ… Prismview Player 11 No fix yet Fix from $2,3002020-02-10 CRITICAL 9.8 CVE-2014-8739EPSS 92% Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Sol… Creative Contact Form 1.0.0 / 2.0.1+ Fix from $2,3002020-02-08 HIGH 8.8 CVE-2013-3591EPSS 43% vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability Vtiger Crm No fix yet Fix from $1,9502020-02-07